# Amazon Web Services MCP connector

Connect Amazon Web Services to Elaichi and Claude, ChatGPT, Cursor or the Elaichi Agent can list your AWS accounts, IAM users, roles, policies, Security Hub findings and GuardDuty detectors, each request running inside the connected access and logged.

Source: https://elaichi.ai/connectors/aws/

## Facts

| | |
| --- | --- |
| Application | Amazon Web Services |
| Category | Cloud Storage |
| AI tools | 90 |
| Authentication | Connects with an API key |
| Bring your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once Amazon Web Services is connected

- List IAM users without an MFA device
- Show high severity Security Hub findings from this week
- Which accounts in our organization have no GuardDuty detector

## Connect Amazon Web Services in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Amazon Web Services.
2. Optionally set Share with, then press Connect.
3. Paste an Amazon Web Services API key. One person generates a token in Amazon Web Services and pastes it once. Everyone else works through Share with, and never sees it.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Amazon Web Services tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Amazon Web Services MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Amazon Web Services MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Amazon Web Services MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Amazon Web Services to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Amazon Web Services tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Amazon Web Services through Elaichi

### Triage Security Hub findings before standup

Security. Ask for the open Security Hub findings across your Amazon Web Services accounts, grouped by severity, and get a short list of what needs a person today.

### Find users without MFA or with stale keys

IT. Pull the IAM users, their access keys and their MFA devices in one ask, then chase the people who still sign in with a password alone.

### Collect evidence for the quarterly audit

Compliance. Generate a fresh credential report, read the account password policy and list the enabled Security Hub standards, then hand the auditor exactly what they asked for.

### Map the organization and its policies

Cloud platform. List every account, root and organizational unit in Amazon Web Services Organizations, and see which policies are attached where before you move a workload.

### Keep the account inventory current for chargeback

Finance. List all Amazon Web Services accounts in the organization with their owning unit so cost allocation matches how the business is actually structured.

### Review how people get into AWS

Internal audit. List the SAML and OIDC identity providers and the IAM roles they can assume, and confirm that federated sign-in is set up the way the policy says.

## Frequently asked questions

### How do I connect Amazon Web Services to Claude?

Two steps. In Elaichi, choose Amazon Web Services, paste the API key from your AWS account, and the connection is live, with no OAuth application to register and no client ID or secret to generate. Then open Claude, go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp as the endpoint. Claude asks you to sign in to Elaichi, and from then on it can work with your Amazon Web Services accounts, IAM and Security Hub.

### Does Amazon Web Services work with ChatGPT and Cursor as well as Claude?

Yes. Once Amazon Web Services is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Amazon Web Services once and every client you use picks it up.

### What can an AI agent actually do with my Amazon Web Services data?

With Amazon Web Services connected, an agent can list the accounts, roots and organizational units in your organization, read IAM users, roles, policies, access keys and MFA devices, generate and read a credential report, and pull Security Hub findings, enabled standards and controls along with GuardDuty detectors. That means questions like "which IAM users have no MFA device" or "show me this week's high severity findings" get answered from live records. Short, concrete asks work better than long sentences.

### Does connecting Amazon Web Services give the AI access to every account and IAM permission?

No. The AI can only reach what the connected Amazon Web Services API key is allowed to reach, and each person still signs in to Elaichi as themselves. Elaichi can then narrow that access further, by team or by action, but it can never widen what the key itself is permitted to do in Amazon Web Services.

### Can my team share one Amazon Web Services connection?

Yes. One person connects Amazon Web Services in Elaichi and shares the connection with a team, and nobody else on that team ever sees or handles the API key. Each teammate still signs in to Elaichi as themselves, so the audit log records who asked for the IAM users or the Security Hub findings, not just that someone did.

### Can I stop an agent from changing things in Amazon Web Services?

Yes. This Amazon Web Services connector is almost entirely read-only, and the one action that creates something, generating a credential report, can be restricted on its own. A restricted action is never advertised to Claude, ChatGPT, Cursor or any other client, so no prompt, however worded, can reach it.

### What happens to an Amazon Web Services connection when someone leaves?

Offboarding a person in Elaichi ends their access to Amazon Web Services through every client at once. If they connected a shared Amazon Web Services account, that connection keeps working for everyone it was shared with. Disconnecting Amazon Web Services once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client at the same time.

### Does the Amazon Web Services MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Amazon Web Services is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

## All 90 Amazon Web Services tools

Every tool below is callable through https://api.elaichi.ai/mcp once Amazon Web Services is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all Amazon Web Services organizations accounts** (List). Every account in the organization, in one global sweep — never fan out per region. Account.Paths materialises grouping_path at zero extra cost, so the recursive ListParents climb is only a fallback. Map state from Account.State, not Account.Status, which retires 2026-09-09 and has no CLOSED value. JoinedTimestamp is the org-join date, not the creation date. An empty page is not a terminator: loop until NextToken is null. A standalone account returns AWSOrganizationsNotInUseException (400).
- **List all Amazon Web Services organizations roots** (List). The organization root. Exactly one call ever — the quota 'Roots in an organization: 1' is not adjustable, and the throttle is 1 req/s. Root has no Path field (only OUs do), so synthesize o-<orgId>/r-<rootId>/. No created_at exists on Root.
- **List all Amazon Web Services organizations ous** (List). Organizational units under one parent, walked breadth-first. Nesting is capped at 5 levels and is not adjustable, so recursion is bounded and needs no cycle guard. Preferred over ListChildren because it returns {Arn, Id, Name, Path} inline and avoids a DescribeOrganizationalUnit per OU at a 2 req/s throttle. No created_at exists on OrganizationalUnit either.
- **List all Amazon Web Services organizations policies** (List). Service control policies. Filter is required and single-valued, so RCPs are a second call with Filter=RESOURCE_CONTROL_POLICY. Management account or delegated administrator only. Filter out the AWS-managed p-FullAWSAccess or target counts are dominated by noise.
- **Get single Amazon Web Services organizations policy by ID** (Get). One SCP with its document. Policy.Content is plain JSON and must NOT be URL-decoded — the opposite of IAM's GetPolicyVersion. Applying the IAM decode here mangles the policy.
- **List all Amazon Web Services organizations policy targets** (List). Where one SCP is directly attached. Returns direct attachments only; inheritance must be computed from the OU tree because DescribeEffectivePolicy explicitly excludes SCPs — its PolicyType enum has no SERVICE_CONTROL_POLICY entry.
- **List all Amazon Web Services iam account authorization details** (List). The primary IAM collector. One paginated sweep returns every user, group, role and policy with GroupList, AttachedManagedPolicies, inline policy documents, Tags and PermissionsBoundary — replacing four of the eight per-user calls. It does NOT cover access keys, MFA devices or login profiles. IAM policy documents here are URL-encoded (RFC 3986): decode only if the string contains %7B, never if it starts with {.
- **List all Amazon Web Services iam users** (List). IAM users. Returns UserId, UserName, Arn, Path, CreateDate and PasswordLastUsed only — no Tags, no PermissionsBoundary. IAM users have no email and no display name anywhere in the API. PasswordLastUsed is console sign-in only, records at most one sign-in per 5-minute window, began 2014-10-20, and has a documented gap from 2018-05-03 22:50 PDT to 2018-05-23 14:08 PDT. A key-only user reports no_information forever — that is not 'never signed in'.
- **List all Amazon Web Services iam roles** (List). IAM roles. ListRoles DOES return AssumeRolePolicyDocument — the omission list names only PermissionsBoundary, RoleLastUsed and Tags — so GetRole is needed only for last_used_at, boundary and tags. Roles have no long-term credentials and no API lists any, so has_static_keys is structurally false and key_count structurally 0.
- **List all Amazon Web Services iam policies** (List). Managed policies. Scope=Local means customer-managed (is_custom). The response already carries DefaultVersionId, so GetPolicy can be skipped and GetPolicyVersion called directly. AttachmentCount (grants) and PermissionsBoundaryUsageCount (restricts) are separate numbers — summing them destroys a security-relevant distinction.
- **Get single Amazon Web Services iam account password policy by ID** (Get). The account password policy. A 404 NoSuchEntity here means no policy is configured, so AWS defaults apply — a WEAKER posture. Render it as 'not configured', never as 'unknown', and never as a pass. IAM has no lockout threshold and no breached-password list at all.
- **Create a Amazon Web Services iam generate credential report** (Create). Starts the credential report job. WARNING: iam:GenerateCredentialReport is access level Write in the Service Authorization Reference, so it will not appear in a policy built by filtering for read access. Without it GetCredentialReport returns 410. Enabling this is a deliberate decision, not a default.
- **Get single Amazon Web Services iam credential report by ID** (Get). The credential report: base64 CSV with sentinels N/A, no_information, not_supported and uppercase TRUE/FALSE. Returns 410 if nobody generated one. It caps at the first two access keys per user and omits service-specific credentials entirely, so it is not the source of truth for static_credentials.
- **List all Amazon Web Services iam access keys** (List). Access keys for one user, max 2. Access keys never expire — expires_at is structurally null, not unknown. last_used_at needs a separate GetAccessKeyLastUsed call per key; access keys are the only credential type that has last-used data at all.
- **List all Amazon Web Services iam MFA devices** (List). MFA devices for one user. The response carries NO device type — type must be inferred from the SerialNumber shape, and FIDO/passkey vs TOTP is not cleanly distinguishable. Mark any mfa_methods value as derived.
- **Get single Amazon Web Services iam login profile by ID** (Get). Console password metadata for one user. A 404 NoSuchEntity is the ANSWER, not an error: it means has_console_access is false. Surfacing it as an integration error turns every programmatic-only user into noise.
- **List all Amazon Web Services iam oidc providers** (List). OIDC identity providers in the account. Returns ARNs only — the issuer URL and audience list need GetOpenIDConnectProvider per ARN. Not paginated.
- **Get single Amazon Web Services iam oidc provider by ID** (Get). One OIDC provider. Url is stored WITHOUT the https:// scheme while trust-policy condition keys use the bare host — normalise both sides before joining. ClientIDList is the registered audience and can disagree with the :aud condition key; the trust policy is what actually gates the assume. A role trusting this provider with no :sub condition can be assumed by any subject from the issuer — model 'no sub condition' as its own state, never as an empty list.
- **List all Amazon Web Services iam saml providers** (List). SAML identity providers in the account. Returns ARNs, ValidUntil and CreateDate. Not paginated. A federated trust to one of these is an external-trust edge on any role whose trust policy names it under Principal.Federated.
- **List all Amazon Web Services securityhub findings** (List). ASFF findings. Check ListFindingAggregators FIRST: if cross-region aggregation is on, calling the aggregation region returns everything and fanning out duplicates it all. Compliance.Status has only PASSED|WARNING|FAILED|NOT_AVAILABLE — there is NO NOT_APPLICABLE, and NOT_AVAILABLE conflates 'not applicable' with 'could not check'. Findings whose Config evaluation returned NOT_APPLICABLE are auto-archived after 3 days, so RecordState must explicitly include ARCHIVED or they vanish. Archived findings are permanently deleted after 30 days. Findings over 240 KB have Resource.Details silently stripped.
- **List all Amazon Web Services securityhub enabled standards** (List). Standards enabled in this region. enabled_standards is a Security Hub concept only — the other seven AWS security services have no notion of a compliance standard, and their feature toggles must not be forced into this field. standardVersion is not a field: the version is embedded in the standard ARN (.../cis-aws-foundations-benchmark/v/1.2.0) and must be string-parsed.
- **Get single Amazon Web Services securityhub hub by ID** (Get). Whether Security Hub is enabled in this region, and which field mapping applies. A 404 or 401 here is DATA — Security Hub is simply not enabled — not an integration failure. ControlFindingGenerator branches the whole finding mapping: SECURITY_CONTROL uses Compliance.SecurityControlId and Compliance.AssociatedStandards; STANDARD_CONTROL has those absent and needs ProductFields.StandardsArn or StandardsGuideArn and ProductFields.ControlId or RuleId. SubscribedAt is enablement time, not an evaluation time — it must not be mapped to last_evaluated_at.
- **List all Amazon Web Services securityhub security controls** (List). Control metadata, fetched once per collection and cached — never per finding. This is the only source of SeverityRating, the control's inherent risk. Severity.Label on a finding is INFORMATIONAL on every PASSED finding because it describes the outcome, not the control.
- **List all Amazon Web Services guardduty detectors** (List). Detector ids in this region — one detector per region per account. Returns ids only.
- **List all Amazon Web Services guardduty list findings** (List). Finding ids, max 50 per page. This returns ids ONLY — GetFindings is mandatory to hydrate them. ListFindings defaults to returning archived and unarchived findings mixed together; decide explicitly rather than inheriting the default.
- **Get single Amazon Web Services guardduty get finding by ID** (Get). Hydrates a batch of up to 50 finding ids. severity is a Double with no severityLabel field anywhere — emit the raw number and mark any band as derived. There is no state field; the closest is service.archived, and service itself is optional. title is optional — fall back to type. resource has no single path: resource.resourceType discriminates about 20 mutually exclusive sub-objects, some of them arrays.
- **Get single Amazon Web Services guardduty detector by ID** (Get). One detector's configuration. status is the enablement signal. updatedAt is a configuration-change timestamp, NOT an evaluation timestamp — mapping it into last_evaluated_at would be a lie to the consumer.
- **List all Amazon Web Services inspector 2 account status** (List). Inspector v2 enablement per account. state.status is the enablement signal. There is NO timestamp anywhere in this response, so last_evaluated_at is unreadable for Inspector — record it as such rather than substituting a config timestamp.
- **List all Amazon Web Services inspector 2 coverage statistics** (List). Scan coverage counts per resource type. NOTE: this operation is NOT in the verified aws-operations.md reference — it is the only plausible source for scan_coverages and must be confirmed against the live API before this method is trusted.
- **List all Amazon Web Services inspector 2 findings** (List). Vulnerability findings. NOTE: this operation is NOT in the verified aws-operations.md reference — it is the only plausible source for vulnerability_findings and must be confirmed against the live API before this method is trusted.
- **List all Amazon Web Services config recorders** (List). Configuration recorders in this region. NOT paginated. NoSuchConfigurationRecorderException is DATA — AWS Config is off — not a failure. The operation now accepts only one recorder per request.
- **List all Amazon Web Services config recorder status** (List). Whether the recorder is actually recording. AWS Config is one of only two of the eight security services with a real last_evaluated_at: lastStatusChangeTime and configSnapshotDeliveryInfo.lastSuccessfulTime. NOT paginated.
- **List all Amazon Web Services config aggregate compliance** (List). Per-(rule, account, region) compliance across the whole organization in one paged call, with no AssumeRole per account — Limit up to 1000. Counts arrive as {CappedCount, CapExceeded}, not an integer: when CapExceeded is true the count is a CEILING, and mapping it as exact publishes wrong numbers on exactly the largest rules. INSUFFICIENT_DATA is returned but cannot be used as a filter value, and the aggregate variant accepts only COMPLIANT and NON_COMPLIANT as filters despite the enum listing four.
- **List all Amazon Web Services config rule evaluation status** (List). The ONLY source of real Config timestamps. DescribeComplianceByConfigRule carries no timestamp at all, so pairing is mandatory — substituting our own fetch time would be exactly the staleness lie this model exists to prevent. Use LastSuccessfulEvaluationTime (evaluation), not LastSuccessfulInvocationTime (invocation).
- **List all Amazon Web Services accessanalyzer analyzers** (List). IAM Access Analyzer analyzers. status == ACTIVE is the enablement signal, and this is one of only two of the eight security services with a genuine last_evaluated_at: lastResourceAnalyzedAt.
- **Get single Amazon Web Services macie session by ID** (Get). Macie v2 enablement. Two traps: Macie returns HTTP 200 with an EMPTY BODY when it is not enabled and reached via AWS Config, so an empty 200 means not-enabled; and status PAUSED means enabled-but-suspended, not disabled.
- **List all Amazon Web Services identitystore users** (List). Identity Center users. ListUsers returns complete User objects — UserId, UserName, DisplayName, Emails, UserStatus and CreatedAt — so DescribeUser adds nothing for bulk sync. MFA registration state is NOT AVAILABLE through any public API (the console uses an undocumented sso-directory operation with no published wire contract). last_sign_in_at is NOT AVAILABLE either — only CloudTrail UserAuthentication events carry it. has_static_credentials and has_console_access are IAM-only concepts here.
- **List all Amazon Web Services SSO instances** (List). Identity Center instances — the bootstrap for IdentityStoreId, InstanceArn, PrimaryRegion and Regions. Capped at 10 instances; do not blindly take [0]. Calling in the WRONG region returns an empty list, not an error, which is indistinguishable from 'the customer does not use Identity Center' — sweep candidate regions rather than trusting one empty result. Note the host is sso.<region>.amazonaws.com, not sso-admin.*.
- **List all Amazon Web Services s 3 buckets** (List). All buckets. Pagination is MANDATORY, not an optimisation: unpaginated requests are rejected outright for accounts with a bucket quota above 10,000, and BucketRegion is only returned on paginated requests — without it every bucket needs an extra GetBucketLocation. BucketArn is now returned; use it as provider_ref rather than constructing arn:aws:s3:::<name>, which is wrong outside the aws partition. Directory buckets (S3 Express) are invisible here — a disjoint namespace under s3express-control.
- **List all Amazon Web Services s 3 bucket public access block** (List). Bucket-level Block Public Access. NoSuchPublicAccessBlockConfiguration (404) means not configured — all four flags false — and must not be read as blocked. BlockPublicAcls and BlockPublicPolicy are WRITE-TIME GUARDS ONLY: AWS states enabling them does not affect existing policies or ACLs. Only IgnorePublicAcls and RestrictPublicBuckets change effective read access, so computing exposure from the two Block flags produces false clean results. Effective BPA is the account setting OR the bucket setting, per flag. Never map a 403 AccessDenied this way — 'not configured' and 'cannot see' are opposite security conclusions. The collector must be region-sharded: a per-bucket GET sent to the wrong region returns 301, 307, 400 or AuthorizationHeaderMalformed.
- **List all Amazon Web Services s 3 bucket policy status** (List). Whether the bucket policy grants public access. This is the ONLY policy-derived signal available cross-account: GetBucketPolicy returns 405 Method Not Allowed for a caller outside the bucket owner's account regardless of IAM. Returns an empty document rather than erroring when there is no policy. Never map a 403 AccessDenied this way — 'not configured' and 'cannot see' are opposite security conclusions. The collector must be region-sharded: a per-bucket GET sent to the wrong region returns 301, 307, 400 or AuthorizationHeaderMalformed.
- **List all Amazon Web Services s 3 bucket policy** (List). The bucket policy document. NoSuchBucketPolicy (404) means no policy, not a failure. Cross-account this returns 405 Method Not Allowed regardless of IAM — map 405 to permission_denied, never to 'no policy'. The document is plain JSON, NOT URL-encoded. Never map a 403 AccessDenied this way — 'not configured' and 'cannot see' are opposite security conclusions. The collector must be region-sharded: a per-bucket GET sent to the wrong region returns 301, 307, 400 or AuthorizationHeaderMalformed.
- **List all Amazon Web Services s 3 bucket acl** (List). Bucket ACL grants. Public means a Grantee.URI of http://acs.amazonaws.com/groups/global/AllUsers or .../global/AuthenticatedUsers. .../s3/LogDelivery is benign — do not flag it. AuthenticatedUsers is not anonymous (requests must be signed) but means any AWS account on earth, so keep it distinguishable rather than folding it into anonymous access. Never map a 403 AccessDenied this way — 'not configured' and 'cannot see' are opposite security conclusions. The collector must be region-sharded: a per-bucket GET sent to the wrong region returns 301, 307, 400 or AuthorizationHeaderMalformed.
- **List all Amazon Web Services s 3 bucket encryption** (List). Default encryption. Since January 2023 SSE-S3 is applied to every bucket by default, so 'no default encryption' is an obsolete control and this rarely 404s — the real control is SSEAlgorithm == AES256, i.e. not a customer-managed key. SSEAlgorithm has FOUR values: AES256, aws:kms, aws:kms:dsse, aws:fsx. KMSMasterKeyID may be a key id, an ARN or an ALIAS — store the raw string with a discriminator. The docs are internally inconsistent (KMSMasterKeyID vs KMSKeyID); parse both. ServerSideEncryptionConfigurationNotFoundError has no documented Errors section, so treat an unrecognised 404 as not_collected, never as a pass. Never map a 403 AccessDenied this way — 'not configured' and 'cannot see' are opposite security conclusions. The collector must be region-sharded: a per-bucket GET sent to the wrong region returns 301, 307, 400 or AuthorizationHeaderMalformed.
- **List all Amazon Web Services s 3 bucket versioning** (List). Versioning state. Returns an EMPTY document with no Status element at all when versioning was never enabled — absent is not the same as Suspended. Never map a 403 AccessDenied this way — 'not configured' and 'cannot see' are opposite security conclusions. The collector must be region-sharded: a per-bucket GET sent to the wrong region returns 301, 307, 400 or AuthorizationHeaderMalformed.
- **List all Amazon Web Services s 3 bucket object lock** (List). Object Lock. Returns only ObjectLockEnabled (single valid value Enabled) and an optional default rule. retention_locked is NOT a real S3 field: the closest honest mapping is Mode == COMPLIANCE, which is a default for FUTURE objects and says nothing about what is in the bucket now. Legal holds and per-object retention are per object version and would need unbounded per-object calls. Never map a 403 AccessDenied this way — 'not configured' and 'cannot see' are opposite security conclusions. The collector must be region-sharded: a per-bucket GET sent to the wrong region returns 301, 307, 400 or AuthorizationHeaderMalformed.
- **List all Amazon Web Services s 3 bucket lifecycle** (List). Lifecycle rules. NoSuchLifecycleConfiguration (404) means no rules, not a failure. Never map a 403 AccessDenied this way — 'not configured' and 'cannot see' are opposite security conclusions. The collector must be region-sharded: a per-bucket GET sent to the wrong region returns 301, 307, 400 or AuthorizationHeaderMalformed.
- **List all Amazon Web Services s 3 bucket logging** (List). Server access logging. Returns an EMPTY document with no LoggingEnabled element when logging is off, rather than erroring. Never map a 403 AccessDenied this way — 'not configured' and 'cannot see' are opposite security conclusions. The collector must be region-sharded: a per-bucket GET sent to the wrong region returns 301, 307, 400 or AuthorizationHeaderMalformed.
- **List all Amazon Web Services s 3 bucket replication** (List). Replication rules and destination buckets. ReplicationConfigurationNotFoundError has no documented Errors section, so an unrecognised 404 must degrade to not_collected, never to a pass. Never map a 403 AccessDenied this way — 'not configured' and 'cannot see' are opposite security conclusions. The collector must be region-sharded: a per-bucket GET sent to the wrong region returns 301, 307, 400 or AuthorizationHeaderMalformed.
- **List all Amazon Web Services s 3 bucket tagging** (List). Bucket tags. The not-configured error code is NoSuchTagSet — singular, NOT NoSuchTagSetError — and means no tags, not a failure. Never map a 403 AccessDenied this way — 'not configured' and 'cannot see' are opposite security conclusions. The collector must be region-sharded: a per-bucket GET sent to the wrong region returns 301, 307, 400 or AuthorizationHeaderMalformed.
- ...and 40 more tools. Call `tools/list` via the MCP endpoint, or see the full catalog via the API, for the complete set.
